PT-2026-81202 · Unknown · Ashauthentication
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 3.10.5 through 4.14.1
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.12
Description
Improper authentication allows purpose-limited JSON Web Tokens (JWTs) to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The helper function
retrieve from bearer/3 verifies the signature of an Authorization: Bearer JWT and rejects tokens with an act claim, but fails to verify if the token's purpose claim equals user. When the resource is configured with require token presence for authentication? set to false, the validate token/3 helper returns {:ok, nil} without consulting the token resource, bypassing downstream purpose checks. Consequently, valid, non-expired JWTs issued for narrow purposes—such as the sign in token emitted by WebAuthn or the Password strategy—are accepted as general-purpose bearer credentials, granting full current user assignment. An attacker who obtains a valid sign in token can authenticate as the target subject, bypassing one-time-use and revocation semantics. This requires the application to use retrieve from bearer/3 on a reachable route and employ either WebAuthn or the Password strategy with sign in tokens enabled? set to true.Recommendations
Update ash authentication to version 4.14.2 or later.
Update ash authentication to version 5.0.0-rc.13 or later.
Set
require token presence for authentication? to true to enforce purpose verification against the stored token record.
Restrict access to routes utilizing the retrieve from bearer/3 helper function.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication